exam questions

Exam MS-100 All Questions

View all questions & answers for the MS-100 exam

Exam MS-100 topic 3 question 34 discussion

Actual exam question from Microsoft's MS-100
Question #: 34
Topic #: 3
[All MS-100 Questions]

Your network contains an on-premises Active Directory domain named contoso.com. The domain contains a Microsoft Exchange Server 2019 organization.
You plan to sync the domain to Azure Active Directory (Azure AD) and to enable device writeback and group writeback.
You need to identify which group types will sync from Azure AD.
Which two group types should you identify? Each correct answer presents part of the solution.
NOTE: Each correct selection is worth one point.

  • A. an Office 365 group that uses the Assigned membership type
  • B. a security group that uses the Dynamic Device membership type
  • C. an Office 365 group that uses the Dynamic User membership type
  • D. a security group that uses the Assigned membership type
  • E. a security group that uses the Dynamic User membership type
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
VP11
Highly Voted 5 years, 3 months ago
The Group writeback feature does not handle security groups or distribution groups.
upvoted 25 times
hufflepuff
2 years, 8 months ago
This is no longer correct - In AD Connect V2 all are supported. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-group-writeback-v2
upvoted 10 times
kerberos99
2 years, 5 months ago
Still in Public Preview…
upvoted 2 times
...
...
...
sovis29088
Highly Voted 3 years, 8 months ago
This question conflicts with a previous one a page or two back where the correct answer indicated that an AzureAD security group would get written back to local AD as a security group if the group writeback feature was enabled. In the discussion for that question, several people mentioned that only Office 365 groups get written back which seems to be the case here.
upvoted 17 times
...
BigDazza_111
Most Recent 2 years, 1 month ago
Selected Answer: AC
correct 'There are two versions of group writeback. The original version is in general availability and is limited to writing back Microsoft 365 groups to your on-premises Active Directory instance as distribution groups. The new, expanded version of group writeback is in public preview and enables the following capabilities: You can write back Microsoft 365 groups as distribution groups, security groups, or mail-enabled security groups. You can write back Azure AD security groups as security groups. All groups are written back with a group scope of Universal. You can write back groups that have assigned and dynamic memberships.'
upvoted 1 times
...
JCkD4Ni3L
2 years, 2 months ago
Selected Answer: AC
Well, at the time of the writing of this question the answer was A & C, now it is A,B,C,D and E. Since we can only choose 2, have to answer the question in a more legacy context, thus A and C.
upvoted 1 times
...
RenegadeOrange
2 years, 11 months ago
ABCDE In AD Connect V2 all are supported. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-group-writeback-v2
upvoted 13 times
Paolo2022
2 years, 7 months ago
That didn't use to be the case, that's why the mix of old questions, assuming the limitation to O365 groups, and new ones with a broader sync scope can lead to confusion. See the link provided in other comments already: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-group-writeback-v2
upvoted 1 times
...
...
bill1982
2 years, 11 months ago
Azure AD Connect group writeback Article 07/15/2022 7 minutes to read 2 contributors Group Writeback is the feature that allows you to write cloud groups back to your on-premises Active Directory using the Azure AD Connect Sync client. This feature enables you to manage groups in the cloud, while controlling access to on-premises applications and resources. Group Writeback provides the following capabilities: Microsoft 365 groups can be written as Distribution groups, Security groups, or Mail-Enabled Security groups. Azure AD Security groups will be written back as Security groups. All groups are written back to AD as scope universal. Allows you to configure group writeback settings for all M365 groups within a tenant. Nested cloud groups and devices, (if device writeback is also enabled) that are members of groups, enabled for writeback, will be written back with scope universal. Now, you can change the common name in an Active Directory group’s distinguished name when configuring group writeback in Azure AD Connect. You can now configure Azure AD groups to writeback using the Azure AD Admin portal, Graph Explorer, and PowerShell.
upvoted 4 times
...
trexar
3 years, 2 months ago
Selected Answer: AC
Groups writeback enables customers to leverage cloud groups for their hybrid needs. If you use the Microsoft 365 Groups feature, then you can have these groups represented in your on-premises Active Directory. This option is only available if you have Exchange present in your on-premises Active Directory.
upvoted 1 times
...
Boeroe
3 years, 4 months ago
Selected Answer: AC
Only 365 groups are written back if an exchange server is present in the on-premise environment: https://docs.microsoft.com/bs-latn-ba/azure/active-directory/hybrid/how-to-connect-group-writeback
upvoted 2 times
...
tf444
3 years, 6 months ago
There is an exchange server present. Groups writeback enables customers to leverage cloud groups for their hybrid needs. If you use the Microsoft 365 Groups feature, then you can have these groups represented in your on-premises Active Directory. This option is only available if you have Exchange present in your on-premises Active Directory.
upvoted 1 times
...
tf444
3 years, 6 months ago
Q 23 ,topic 3. https://www.examtopics.com/discussions/microsoft/view/48807-exam-ms-100-topic-3-question-23-discussion/
upvoted 1 times
...
tf444
3 years, 6 months ago
IF the group writeback is enabled in the Azure AD Connect configuration so groups created in Azure Active Directory will be synchronized to the on-premise Active Directory. A security group created in Azure Active Directory will be synchronized to the on-premise Active Directory as a security group. in another Q in exam topic.
upvoted 1 times
...
JakeH
3 years, 7 months ago
In exam today
upvoted 1 times
...
fofo1960
3 years, 8 months ago
Tested, and One A & C are correct, Security or Dist groups wont be written back.
upvoted 3 times
...
Eltooth
4 years, 2 months ago
Agree - A & C. Exam topic #2, Q22 Group write back has specific requirements before only M365 groups can sync back...including Exchange Hybrid. https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-group-writeback#pre-requisites
upvoted 4 times
...
MerryWeasel
4 years, 5 months ago
Here are some references: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-device-writeback https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-group-writeback https://docs.microsoft.com/en-us/exchange/hybrid-deployment/set-up-microsoft-365-groups#enable-group-writeback-in-azure-ad-connect
upvoted 2 times
...
mkoprivnj
4 years, 6 months ago
A & C for sure!
upvoted 3 times
...
phvogel
4 years, 8 months ago
The question is really asking which of these groups could you use (I read it as "which two groups must be used together" but only one is required). Writeback only works with Office 365 groups.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...